Chapter 6 Traffic Policy
Figure 6.17 Traffic rule — selecting an action
•Permit — traffic will be allowed by the firewall
•Deny — client will be informed that access to the address or port is denied. The client will be warned promptly, however, it is informed that the traffic is blocked by firewall.
•Drop — all packets that fit this rule will be dropped by firewall. The client will not be sent any notification and will consider the action as a network outage. The action is not repeated immediately by the client (the client expects a response and tries to connect later, etc.).
Note: It is recommended to use the Deny option to limit the Internet access for local users and the Drop option to block access from the Internet.
Log
The following actions can be taken to log traffic: